From dea2186d6b04a5a81355e5d97eef70b73c1e2fa4 Mon Sep 17 00:00:00 2001 From: xavierk Date: Tue, 15 Sep 2026 16:43:41 +0530 Subject: [PATCH] Prepare XBPS repository publication --- Makefile | 10 +++--- README.md | 75 ++++++++++++++++++++++++++++++++++++----- scripts/xbps-publish.sh | 7 ++-- 3 files changed, 76 insertions(+), 16 deletions(-) diff --git a/Makefile b/Makefile index c0f31e4..8c56552 100644 --- a/Makefile +++ b/Makefile @@ -277,28 +277,30 @@ package: package-deb package-rpm # XBPS signing key (separate from SSH authentication key) XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps +XBPS_REVISION ?= 1 package-xbps: stage @echo "=== Building XBPS package ===" cp packaging/xbps/install.sh build/stage/INSTALL cp packaging/xbps/remove.sh build/stage/REMOVE + install -D -m 0644 packaging/fenris.conf build/stage/etc/fenris/fenris.conf chmod 755 build/stage/INSTALL build/stage/REMOVE xbps-create -A x86_64 \ - -n fenris-$(FENRIS_VERSION)_1 \ + -n fenris-$(FENRIS_VERSION)_$(XBPS_REVISION) \ -s "Fenris NVMe wear monitor" \ -S "NVMe wear monitor with persistent TUI" \ -m "Fenris Packaging " \ -H "https://git.bongbetic.com/xavierk/Fenris" \ -l "MIT" \ - -D "python3>=3.10 smartmontools" \ + -D "python3>=3.10 smartmontools>=0" \ -F "/etc/fenris/fenris.conf" \ build/stage - @echo "=== XBPS package built: fenris-$(FENRIS_VERSION)_1.x86_64.xbps ===" + @echo "=== XBPS package built: fenris-$(FENRIS_VERSION)_$(XBPS_REVISION).x86_64.xbps ===" sign-xbps: package-xbps @echo "=== Signing XBPS package ===" xbps-rindex --sign-pkg --privkey $(XBPS_SIGNING_KEY) \ - fenris-$(FENRIS_VERSION)_1.x86_64.xbps + fenris-$(FENRIS_VERSION)_$(XBPS_REVISION).x86_64.xbps @echo "=== XBPS package signed ===" xbps-publish: diff --git a/README.md b/README.md index 1f5940d..01d586b 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ *Observes an NVMe drive's real-world use and translates that history into an understandable endurance outlook.* -Fenris is a persistent TUI monitor backed by a short-lived privileged collector on a systemd timer. It reads SMART data every few minutes, stores compact observation history in SQLite, and recomputes a usage-adjusted theoretical lifespan on every screen render — no fairy dust, just your actual bytes. +Fenris is a persistent TUI monitor backed by a short-lived privileged collector on the host's native scheduler. It reads SMART data every few minutes, stores compact observation history in SQLite, and recomputes a usage-adjusted theoretical lifespan on every screen render — no fairy dust, just your actual bytes. --- @@ -10,7 +10,7 @@ Fenris is a persistent TUI monitor backed by a short-lived privileged collector - **Python ≥ 3.10** (verified at install time) - **smartmontools** (`smartctl` — verified at install time) -- **systemd** with a polkit agent (the collector runs as root oneshot; elevation is exclusively polkit) +- **systemd** or **runit**, with a polkit agent (the collector runs as root; elevation is exclusively polkit) No other OS packages or Python dependencies beyond [Textual](https://textual.textualize.io/) (pinned in the lockfile). @@ -66,6 +66,44 @@ The repo file sets `gpgcheck=1` against the Fenris packaging key (downloaded from the raw URL in `gpgkey`) and `repo_gpgcheck=0` (metadata check left to TLS). +### Void Linux (XBPS) + +Void x86_64 with glibc and runit is the native target. Its XBPS channel is +withheld until the host-acceptance gate passes; do not install proof artifacts +from it. Once a Fenris Release lists XBPS as available, add the permanent +signed repository, refresh its metadata, and install the package: + +```bash +sudo install -d -m 0755 /etc/xbps.d +echo 'repository=https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/x86_64' \ + | sudo tee /etc/xbps.d/fenris.conf +sudo xbps-install -S fenris +``` + +XBPS requires remote repositories to be signed. On the first refresh it +displays the repository signing key embedded in the signed metadata; accept it +only when its RSA SHA256 fingerprint is +`SHA256:AvPMRlKMikPg75u0iKr8AUkxlfU/Ad4k/S4o2M9W4/w`. The public key is also +available at +`https://git.bongbetic.com/xavierk/Fenris-xbps/raw/branch/stable/keys/fenris-xbps-signing.pub`. +For later updates, always refresh first so XBPS fetches the current index: + +```bash +sudo xbps-install -Syu +``` + +The runit service remains dormant after installation. `fenris monitor resume` +creates `/var/service/fenris-collect`; pause removes that link and records a +deliberate disable in the observation history. + +Fenris keeps the observation store root-written and readable by the `fenris` +group. Add each TUI user to that group, then start a new login session before +running Fenris: + +```bash +sudo usermod -aG fenris "$USER" +``` + ### Package signature verification The RPM payload is signed with the Fenris packaging key (RSA 3072). @@ -84,12 +122,12 @@ The packaging public key is published in-repo — no keyservers. See ### Dormant install -A fresh package install is fully dormant. Units are present but disabled; -nothing runs. The only opt-in is the sanctioned toggle: +A fresh package install is fully dormant. Its native scheduler is present but +disabled; nothing runs. The only opt-in is the sanctioned toggle: ```bash -fenris monitor resume # enable timer + open first monitoring period -fenris monitor pause # close the period, disable timer +fenris monitor resume # enable scheduling + open first monitoring period +fenris monitor pause # close the period, disable scheduling ``` ## Development install (make install) @@ -117,6 +155,7 @@ make purge # also removes /etc/fenris and /var/lib/fenris ```bash sudo apt update && sudo apt upgrade fenris # Debian/Ubuntu sudo dnf upgrade fenris # Fedora +sudo xbps-install -Syu # Void Linux ``` ### Development upgrade @@ -133,6 +172,12 @@ What it does: 5. Applies forward-only schema migrations (the store directory is never rebuilt; automatic downgrade does not exist). Rollback: reinstall the previous version and restore `observations.db.bak`. +On Void, pause monitoring first, copy the compatible snapshot back to +`/var/lib/fenris/observations.db`, then force-install the matching older +package version. If that version is no longer indexed, add its retained XBPS +archive to a local repository with `xbps-rindex -a` and use +`xbps-install -R -f fenris-`. Installing an older +package over a newer observation store is unsupported. ## Migration from make install @@ -150,6 +195,7 @@ continuity. Over-installing the package over a `make install` is sudo apt remove fenris # preserves config and store sudo apt purge fenris # also removes config and store sudo dnf remove fenris # preserves config and store +sudo xbps-remove fenris # preserves config and store ``` ### Development removal @@ -174,6 +220,19 @@ sudo systemctl edit fenris-collect.timer No interval key exists in `/etc/fenris/fenris.conf`. Cadence is a systemd concern, not a Fenris configuration key. +On Void, Fenris uses its native runit service instead: its initial collection +is delayed by two minutes and later collections run five minutes after the +previous run finishes. Inspect its state and diagnostics with: + +```bash +sv status fenris-collect +sudo tail -n 50 /var/log/fenris-collect/current +``` + +`fenris status` also reports the separate boot-enabled, runtime-active, +collection outcome, and observation-store freshness facts. A failed collection +is retried at the next interval; it never fabricates missing observations. + ## CLI reference | Command | Behavior | @@ -181,8 +240,8 @@ No interval key exists in `/etc/fenris/fenris.conf`. Cadence is a systemd concer | `fenris` | Opens the TUI (no arguments). | | `fenris status` | Projection facts, enabled/active state, last collect outcome, journal hint on failure or staleness. Never auto-samples. | | `fenris sample` | On-demand collection via the privileged helper. Blocks until the run completes. | -| `fenris monitor pause` | Sanctioned disable — asks for confirmation, then disables the timer and closes the monitoring period. | -| `fenris monitor resume` | Sanctioned enable — enables the timer and opens a monitoring period. No confirmation. | +| `fenris monitor pause` | Sanctioned disable — asks for confirmation, then disables native scheduling and closes the monitoring period. | +| `fenris monitor resume` | Sanctioned enable — enables native scheduling and opens a monitoring period. No confirmation. | | `fenris baseline set ` | CLI-side validation, then polkit-guarded persistence. | | `fenris baseline clear` | Remove the endurance baseline. | | `fenris import ` | Idempotent single-transaction legacy import. | diff --git a/scripts/xbps-publish.sh b/scripts/xbps-publish.sh index 1f7e7c8..3febfc4 100755 --- a/scripts/xbps-publish.sh +++ b/scripts/xbps-publish.sh @@ -84,13 +84,13 @@ for tool in xbps-create xbps-rindex git; do if ! command -v "$tool" &>/dev/null; then echo "ERROR: Required tool not found: $tool" >&2 exit 1 - done + fi done # ── Main ───────────────────────────────────────────────────────────────── VERSION=$(_version) -REVISION=1 +REVISION="${XBPS_REVISION:-1}" PKGVER="fenris-${VERSION}_${REVISION}" XBPS_FILE="${PKGVER}.${ARCH}.xbps" @@ -105,8 +105,7 @@ fi # ── Step 1: Build XBPS package ─────────────────────────────────────────── echo "--- Build XBPS package ---" -_run "make stage" -_run "xbps-create -A ${ARCH} -n ${PKGVER} -s 'Fenris NVMe wear monitor' -S 'NVMe wear monitor with persistent TUI' -m 'Fenris Packaging ' -H 'https://git.bongbetic.com/xavierk/Fenris' -l 'MIT' build/stage" +_run "make XBPS_REVISION=${REVISION} package-xbps" echo "" # ── Step 2: Sign package ─────────────────────────────────────────────────